Editor’s Note: Congressional scrutiny of Chinese AI models has found its operating rhythm, and it runs through the records a company keeps about its own engineering choices. Two House committees asked DoorDash for seven categories of documents by today, starting with every model from a PRC-based or PRC-controlled developer the company has evaluated or used since Jan. 1, 2025, in development, testing, staging or production, and running through its benchmarking, its security testing, its risk assessments, its costs, its AI governance policies and a timeline of what it knew about the distillation allegations against Moonshot AI. The letter is not a subpoena and does not itself compel production or attendance. The detail worth the attention of legal and compliance teams is the briefing roster: the chairmen asked for personnel responsible for AI infrastructure, software security, model evaluation, procurement, and legal or compliance review, the first time in this investigation that any function has been named.

Watch whether the Aug. 21 briefing happens on schedule. The nearer question is what your own answer would look like if the same seven categories arrived tomorrow.


Content Assessment: DoorDash AI inquiry turns model selection into a governance test

Information - 94%
Insight - 94%
Relevance - 92%
Objectivity - 92%
Authority - 91%

93%

Excellent

A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "DoorDash AI inquiry turns model selection into a governance test."


Industry News – Artificial Intelligence Beat

DoorDash AI inquiry turns model selection into a governance test

ComplexDiscovery OÜ Staff

Today is the requested deadline for DoorDash to provide two House committees with seven categories of records concerning Chinese artificial intelligence.

That request begins with every model from a PRC-based or PRC-controlled developer that DoorDash or a subsidiary has evaluated or used since Jan. 1, 2025, in development, testing, staging or production.

The DoorDash inquiry followed a July 6 post, though the investigation it belongs to had been underway since April. That day, Andy Fang, DoorDash’s co-founder and chief technology officer, wrote on X that the company’s AI code reviewer sends lower-level work to Kimi K2.6, an open-weight model from Beijing-based Moonshot AI, and routes more difficult tasks to an American frontier model, Anthropic’s Fable. Internal benchmarking, Fang wrote, showed the split delivered better quality at lower cost without degrading code quality.

Twenty-five days later, the chairmen of the House Select Committee on China and the House Homeland Security Committee sent a joint letter to DoorDash co-founder and Chief Executive Tony Xu. Rep. John Moolenaar of Michigan and Rep. Andrew Garbarino of New York, both Republicans, asked for the documents by Aug. 14 and an in-person briefing by Aug. 21. The select committee’s announcement leaned into the company’s line of business, closing its headline with the words “A Recipe for Risk.”



Inside the seven-category request

A model list is the smallest thing the letter asks for. The seven categories run from that inventory, with developer, version, modifications and deployment details for each, through DoorDash’s own benchmarking, including the methodology behind the internal DashBench tests and how the Kimi K2.6 configuration compared against American and other non-PRC models. The committees also want the security and reliability testing performed on those models, covering artifact integrity, unauthorized modification, anomalous behavior, insecure code generation and data-disclosure risk, and an explanation for any category the company did not test.

The remaining four categories are governance documents. The chairmen asked for the risk assessments and internal communications behind selecting and approving each model, including what DoorDash knew about developer ownership and sanctions exposure and whether it reevaluated anything after July 22; monthly cost and usage figures by function, with contingency plans for replacing the models; the company’s AI governance policies for acquisition, approval, deployment, testing, access control and monitoring; and a timeline of when DoorDash learned of the distillation allegations against Moonshot AI and what it did about them.

Then comes the escalation. The letter asks that personnel responsible for AI infrastructure, software security, model evaluation, procurement, and legal or compliance review appear for an in-person briefing by Aug. 21. When the same chairmen opened this investigation in April with letters to Anysphere and Airbnb, both asked only that appropriate personnel appear. This is the first letter in the investigation to name functions at all, and the first to reach legal or compliance review. Note the disjunctive: the letter asks for whoever performs that review, which at many companies is a compliance officer rather than a lawyer. Either way, the letter treats model selection as a documented governance decision rather than solely an engineering choice.

The letter is not a subpoena and does not itself compel production or attendance, a distinction some early headlines blurred. It asks DoorDash to produce the records and asks its personnel to appear. The chairmen ground the request in House Rules X and XI and in the select committee’s charge under House Resolution 5 to counter the economic, technological, security and ideological threats of the Chinese Communist Party, and they instruct the company to preserve hard-copy and electronic records on the letter’s subject.

DoorDash has signaled cooperation. A spokesperson said in a statement that the company supports American leadership in artificial intelligence, wants the technology’s benefits to reach the wider U.S. economy, and would engage with the committees on using both American frontier models and open-weight systems safely and responsibly.

Cursor and Airbnb received the first letters

The investigation opened April 29 with letters to Anysphere Chief Executive Michael Truell and Airbnb Chief Executive Brian Chesky. The Anysphere letter focused on Composer 2, the coding model the Cursor maker released March 19, which the chairmen said was built on Moonshot’s Kimi K2.5. The Airbnb letter pointed to the company’s reported use of Alibaba’s Qwen models in customer service operations, and to Chesky’s October 2025 comments to Bloomberg that Airbnb relied on Qwen because it was fast and cheap.

Those letters ran on the same clock the DoorDash letter now runs: documents in two weeks, a briefing in three, with deadlines of May 13 and May 20. They also swept broadly. Anysphere was asked for its comparative model evaluations, its assessments of legal, reputational, national security and supply chain risk, its communications about when to disclose the model’s origins to users and investors, and its security audits of the model weights themselves, with reasons if no audit was conducted. Both April letters closed with a preservation directive, instructing each company on receipt to retain hard-copy and electronic records tied to the letter’s subject matter.

The committees say the spring letters produced productive discussions with both companies. Neither side has publicly described those conversations in detail.

A tense summer for Moonshot

The DoorDash letter landed in the middle of Moonshot’s most scrutinized month. On July 16, the Beijing company, which counts Alibaba among its backers, unveiled Kimi K3, a system Moonshot’s own developer documentation puts at 2.8 trillion parameters, a scale the company says no open-source model had reached before. Open-source is Moonshot’s label; the committees’ letters call the same class of release open-weight. Moonshot published the full weights on July 27 through its Hugging Face repository, under the Kimi K3 License, and claimed performance competitive with Anthropic’s newest frontier releases.

Six days later, Michael Kratsios, director of the White House Office of Science and Technology Policy, wrote on X that the administration had information indicating Moonshot built K3 by distilling Anthropic’s Fable model, using an internal platform designed to run large-scale distillation against U.S. systems. The committees cited that statement in their July 31 announcement, writing that Kratsios had said Moonshot may have operated a covert platform for large-scale distillation against American AI models.

Moonshot left NPR’s questions about the accusation unanswered, though the network reported that the company denied the claims through Chinese media. One Moonshot employee, Randy Xian, argued publicly that timing alone made the charge implausible, because K3 shipped roughly two weeks after the Anthropic model it supposedly copied became available. Anthropic, for its part, has said distillation by Chinese labs is real and carries national security risk, while stopping short of tying its findings to K3 specifically, according to NPR.

The chairmen drew a limit around their own allegation, and it is the most useful sentence in the letter for anyone assessing a model already in production. Evidence that a developer may have obtained capabilities through unauthorized distillation does not by itself show that any particular model contains malicious code, compromised weights or another technical defect, the letter says. What it does bear on, in the committees’ view, is the developer’s practices and risk profile, which is a question about the supplier rather than the software.

Whether any of this is unlawful is unsettled, and it is several questions rather than one. NPR reported that distillation has not been tested in court, and that the theories available to an aggrieved model developer run through copyright, trade-secret protection and breach of the terms a user accepts on signup, each with its own problems. Anupam Chander, a Georgetown University law professor, told NPR that AI companies themselves have long argued that learning from others is fair use. Chinese commentators quoted in the state-run Global Times called the DoorDash inquiry politically driven.

Why legal and compliance are named at all

The committees’ April letters read like discovery requests, and for legal, compliance and information governance teams that is the point. The chairmen asked Anysphere and Airbnb for the records a well-governed AI program would generate along the way: model inventories by name, version, developer, business function and access method; comparative evaluations of PRC-origin models against alternatives; risk assessments across legal, reputational, national security and supply chain dimensions; security audit results for the model weights, including checks for backdoors, poisoned weights and hidden data exfiltration, or an explanation for their absence; agreements with inference hosts and subprocessors; and the communications in which those choices were debated.

Scale explains the urgency. In opening the investigation, the chairmen cited estimates that PRC-developed models accounted for roughly 1 percent of global AI workloads in late 2024 and had reportedly grown to an estimated 30 percent by the end of 2025. The letters did not specify how workloads were measured, and both figures arrived with the chairmen’s own hedge: reportedly.

The security-testing record behind the committees’ concern is public, and it concerns a different company’s models. The Airbnb letter pointed to an evaluation by the National Institute of Standards and Technology’s Center for AI Standards and Innovation, published Sept. 30, 2025, which found that the model NIST identified as DeepSeek’s most secure, R1-0528, responded to 94 percent of overtly malicious requests under a common jailbreaking technique, against 8 percent for the U.S. reference models it tested. That evaluation did not test Kimi K2.6, or any Moonshot model, and says nothing about the code review running inside DoorDash.

None of this is confined to companies that took a public position on Chinese models. Any organization running PRC-origin open-weight systems, Kimi, DeepSeek, Qwen or GLM among them, in coding assistance, document processing or customer-facing pipelines now has a template for the questions to expect. A self-hosting posture narrows some questions and leaves others untouched. Running weights on your own infrastructure can reduce what reaches a provider’s servers, but it does not by itself establish that nothing leaves: dependencies, telemetry, tooling and deployment configuration all still matter, and the letters ask for the security testing regardless. The Airbnb letter goes further still, asking for the complete data pathway for every PRC-origin model reached through an API, naming each entity in the processing chain, where it is incorporated and where its servers sit. A company providing a full response would have to disclose that it did not perform the testing.

For legal departments the exposure has a second layer: whether Chinese-origin models sit inside contract review, summarization, transcription or coding tools that touch privileged or attorney work-product material. That diligence runs through vendors. The practical move is to ask every review platform, translation service and transcription vendor in the stack to identify the base models under the hood, by name, version and developer, the same taxonomy the committees use.

What to do before the next letter

The letters themselves are the audit template. Keep a live inventory of every model in the stack and its provenance. Retain the evaluation memos, procurement approvals and security test results that explain how each one got there. Document the decision not to test as carefully as the testing, because the committees ask for reasons when no audit exists. Treat message threads about model choice as records that may be produced, because the April letters asked for exactly those communications. And when a letter arrives, expect it to direct preservation on receipt, as both April letters did.

Preparing a full response on this timeline would be a substantial production exercise. Seven categories in 14 days means custodian identification, collection, review and privilege calls compressed into two weeks, with a second workstream preparing whoever would sit for the briefing a week later. Legal operations teams that have mapped where model-selection records live, in ticketing systems, procurement platforms, chat threads and evaluation dashboards, will spend those weeks reviewing rather than searching.

As of Friday morning, neither the committees nor DoorDash had said publicly whether documents changed hands. The next date identified in the letter is Aug. 21, when the committees have requested an in-person briefing from the specified DoorDash personnel. Behind it sits a policy signal worth reading twice: in the DoorDash letter, as quoted in both committees’ announcements, the chairmen wrote that U.S. companies may adopt PRC open-weight models for competitive capability, lower cost, customization and vendor diversification, and that the federal response should strengthen American open-weight alternatives while applying tailored safeguards in sensitive and high-risk applications. The homeland committee’s announcement added that the investigation examines whether the United States has a sufficient open-weight AI strategy. The letter does not call for a categorical ban on PRC-origin models. What it does ask for is documentation, in volume and on a deadline, which is a different kind of pressure and a nearer one.

The question for everyone else is closer to home: if the next letter named your organization, could you produce your AI model inventory, with the security testing attached, in 14 days?



News sources



Assisted by GAI and LLM Technologies

Additional reading

Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more understandable for practitioners, policymakers, and business leaders.

 

Have a Request?

If you have information or offering requests that you would like to ask us about, please let us know, and we will make our response to you a priority.

ComplexDiscovery OÜ is an independent digital publication and research organization based in Tallinn, Estonia. ComplexDiscovery covers cybersecurity, data privacy, regulatory compliance, and eDiscovery, with reporting that connects legal and business technology developments—including high-growth startup trends—to international business, policy, and global security dynamics. Focusing on technology and risk issues shaped by cross-border regulation and geopolitical complexity, ComplexDiscovery delivers editorial coverage, original analysis, and curated briefings for a global audience of legal, compliance, security, and technology professionals. Learn more at ComplexDiscovery.com.

 

Generative Artificial Intelligence and Large Language Model Use

ComplexDiscovery OÜ recognizes the value of GAI and LLM tools in streamlining content creation processes and enhancing the overall quality of its research, writing, and editing efforts. To this end, ComplexDiscovery OÜ regularly employs GAI tools, including ChatGPT, Claude, Gemini, Grammarly, Midjourney, and Perplexity, to assist, augment, and accelerate the development and publication of both new and revised content in posts and pages published (initiated in late 2022).